-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
-
Severity 2 - Major
-
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.
[CRUC-8169] XSS in the view review history resource through invited reviewers - CVE-2017-18089
Workflow | Original: FE-CRUC Bug Workflow [ 2941852 ] | New: JAC Bug Workflow v3 [ 2954329 ] |
Workflow | Original: FECRU Development Workflow - Triage - Restricted [ 2594763 ] | New: FE-CRUC Bug Workflow [ 2941852 ] |
Labels | Original: CVE-2017-18089 advisory advisory-to-release cvss-medium security xss | New: CVE-2017-18089 advisory advisory-released cvss-medium security xss |
Security | Original: Atlassian Staff [ 10750 ] |
Summary | Original: XSS in the review history resource through invited reviewers - CVE-2017-18089 | New: XSS in the view review history resource through invited reviewers - CVE-2017-18089 |
Description | Original: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review. | New: The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review. |
Labels | Original: CVE-2017-18089 advisory advisory-to-release cvss-medium security | New: CVE-2017-18089 advisory advisory-to-release cvss-medium security xss |
Summary | Original: CVE-2017-18089 | New: XSS in the review history resource through invited reviewers - CVE-2017-18089 |
Description | Original: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to IMPACT via a VULN_INFO. | New: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review. |
Description | Original: Component in Atlassian Crucible from version 4.4.1 before version 4.4.3 allows remote attackers to IMPACT via a VULN_INFO. | New: The review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to IMPACT via a VULN_INFO. |